product update

Google's Gemini Spark Gains Chrome Web-Browsing to Automate Flight Bookings and Errands

TL;DR

Google's agentic AI assistant Spark now integrates with Chrome, letting it use logged-in accounts and saved passwords to handle tasks like researching flights and scheduling apartment viewings. The feature is rolling out in the US now, alongside expanded Spark access for Google AI Pro subscribers in over 160 countries.

2 min read
0

Google has added Chrome web-browsing integration to Spark, its agentic AI assistant, allowing the tool to use a user's logged-in accounts and saved passwords to complete tasks directly in the browser.

According to Google, once a user logs in to Chrome, Spark "can use your logged-in accounts and saved passwords to handle tedious web errands." The company's two provided examples: researching flight options and starting the booking process, and scheduling viewings of apartments. Google has not disclosed a broader list of supported tasks.

Rollout and access

The Chrome integration is rolling out now in the US, with Google saying additional regions will follow. The announcement coincides with an expansion of Spark access to Google AI Pro subscribers in more than 160 countries. Spark also integrates with Google Workspace apps, extending its reach beyond the browser into email, documents, and scheduling tools.

Safety claims

Handing an AI assistant access to passwords and logged-in sessions raises an obvious risk: prompt injection, where malicious instructions hidden on a webpage or in user-generated content hijack the assistant into taking unwanted actions, such as initiating financial transactions or exfiltrating sensitive data.

Google says it is "investing in a layered defense that includes both deterministic and probabilistic defenses to make it difficult and costly for attackers to cause harm." The company has not detailed what these deterministic and probabilistic defenses actually consist of, nor published any benchmark or red-team results demonstrating their effectiveness against prompt injection attacks.

As a guardrail, Google says Spark will not complete payments autonomously. Purchases are routed back to the user for final review and confirmation, meaning the assistant can advance a transaction to checkout but cannot execute it independently.

Engadget, which first reported the update, has asked Google for further detail on the scope of the integration and has not yet received a response.

What this means

This release fits a broader pattern among AI labs: shipping browser-connected agents before publishing rigorous, independently verifiable security guarantees. Prompt injection remains an unsolved problem industry-wide, and Google's description of its defenses—"layered," "deterministic and probabilistic"—is vague enough that it should be read as a claim, not a settled fact. The decision to keep payment completion in human hands is a sensible interim safeguard, but it also underscores that Google isn't yet confident enough in its own injection defenses to let Spark handle money unsupervised.

The narrow use cases Google highlighted—flight research and apartment viewing scheduling—suggest this is an early, limited rollout rather than a general-purpose browsing agent. Expect scope to widen alongside the wider AI Pro rollout across 160+ countries, but expect scrutiny of the safety claims to widen too, particularly from security researchers who have spent the past year demonstrating how easily browser-using agents can be manipulated by adversarial web content.

Related Articles

product update

Google Launches Gemini Desktop App for Windows, Following April's macOS Debut

Google has released the Gemini for desktop app on Windows, five months after its macOS launch in April 2026. The app offers instant AI access via an Alt + Space shortcut, including Gemini Spark agent features and Nano Banana image/video generation.

product update

Augment Code Claims 4.5x Developer Output Increase From Internal 'Software Factory' of AI Agents

Augment Code says its internal 'software factory'—a network of specialized agents built on its Cosmos platform—drove a 4.5x increase in size-adjusted developer output and cut median PR merge time from 11.2 to 3.1 hours over nine months. The company frames this as evidence that once AI writes nearly all new code, the bottleneck shifts to review, verification, and incident response.

product update

AWS Shows How to Build Interactive MCP Apps on Amazon Bedrock AgentCore

AWS published a technical walkthrough for building MCP Apps—interactive HTML widgets rendered inside AI hosts like ChatGPT and Claude—using Amazon Bedrock AgentCore's runtime and Gateway components. The reference implementation, a unicorn rental app, demonstrates host-agnostic rich UI delivered through a single MCP server.

product update

Meta's Muse AI Agent Hits No. 2 on US App Store With 83,000 iOS Downloads

Meta's new agentic AI app Muse has surpassed 83,000 iOS downloads in the US and climbed to No. 2 on the App Store, according to Sensor Tower data. The launch trails Meta's own Threads and Meta AI debuts, as well as ChatGPT's early growth rate.

Comments

Loading...